After a security policy change, users complain that they cannot upload files to a custom web application. The rule allows the custom application 'webapp' and Content-ID is enabled. What is the most likely cause?
Trap 1: The application 'webapp' is not allowed due to an application…
An application override forces traffic to a specified App-ID rather than blocking it, so it would not deny 'webapp' when the rule allows that application. It is tempting because overrides change App-ID classification, and it would be correct if traffic were being matched to the wrong application.
Trap 2: SSL decryption is not enabled.
SSL decryption affects visibility into encrypted sessions, but the policy already permits 'webapp' by App-ID, so uploads are not blocked for that reason. It is tempting because decryption is needed for Content-ID inspection, and it would be correct if the application were unidentified due to encrypted traffic.
Trap 3: App-ID is not identifying the application correctly.
App-ID correctly identifying 'webapp' would permit the traffic, so misidentification is not the likely cause when the rule already names that custom application. It is tempting because App-ID underpins policy matching, and it would be correct if the application were being classified as unknown-tcp or a different App-ID.
- A
The application 'webapp' is not allowed due to an application override.
Why it fails: An application override forces traffic to a specified App-ID rather than blocking it, so it would not deny 'webapp' when the rule allows that application. It is tempting because overrides change App-ID classification, and it would be correct if traffic were being matched to the wrong application.
- B
SSL decryption is not enabled.
Why it fails: SSL decryption affects visibility into encrypted sessions, but the policy already permits 'webapp' by App-ID, so uploads are not blocked for that reason. It is tempting because decryption is needed for Content-ID inspection, and it would be correct if the application were unidentified due to encrypted traffic.
- C
A file blocking profile is blocking the upload.
With Content-ID enabled, the firewall inspects the upload and a file blocking profile applied to the matching rule drops the transfer if the file type is blocked. The application itself is permitted, so the file blocking profile is the likely cause.
- D
App-ID is not identifying the application correctly.
Why it fails: App-ID correctly identifying 'webapp' would permit the traffic, so misidentification is not the likely cause when the rule already names that custom application. It is tempting because App-ID underpins policy matching, and it would be correct if the application were being classified as unknown-tcp or a different App-ID.